Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] Block IP's from showing 404's in the dashboard #332

Open
bryandugan opened this issue Feb 21, 2025 · 2 comments
Open

[FR] Block IP's from showing 404's in the dashboard #332

bryandugan opened this issue Feb 21, 2025 · 2 comments
Labels
enhancement New feature or request

Comments

@bryandugan
Copy link

We are currently running Tenable security scans on our sites, which try to access any common URL with a security vulnerability and report it back to the security team. Our scans run once a week, and the list of URLs it tries to access can be in the hundreds, with new URLs added each scan, which, over time, has brought my 404 list up to nearly 1,000. This makes it difficult for me to actually manage 404's that normal users have tried to access and make sure those are resolved.

It would be beneficial to have some sort of settings section that will allow us to block a list of IP addresses from showing up in the dashboard and the number of 404s that need to be resolved.

@bryandugan bryandugan added the enhancement New feature or request label Feb 21, 2025
@khalwat
Copy link
Contributor

khalwat commented Feb 24, 2025

Would you want to block IP addresses, or block URLs?

@bryandugan
Copy link
Author

I would like to block specific IP addresses from allowing results to show if possible. Unless you think ignoring URLs from showing up would be better in this scenario. The IS team sent me a list of about 10 IPs in which the scans run from.

In one of the scans, the Tenable bot searched all Sendgrid directories with sensitive information to see if the bot could access those pages. It added around 50 URLs to the list when it tried to test for security vulnerabilities there. Or it would try to access things like the wp-config file in WordPress, .env files, config files, or common dashboard URLs such as /admin, /dashboard along with variations of other CMS dashboard URL's.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants